Cur1Downloader
- First seen
- 2021-05-15 00:00:00
- Malware type
- downloader
- Profile updated
- 2026-07-07 14:37:43
Targeted industries: financial-services government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:kr country_code:us country_code:jp
Context
Cur1Downloader is a downloader linked to the Lazarus group, potentially targeting sectors in South Korea, the United States, and Japan. It is used to download additional payloads onto compromised systems.
Reports & references
- blogs.jpcert.or.jp — Dangerouspassword (report)
- mp.weixin.qq.com — Nnlqubpx8Xz3Hcr5U Isjq (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Cur1 Downloader (report)
- Kaspersky — 108383 (report)
- twitter.com — 1595365451495706624 (report)